RiskAnalytics
- Company typePrivate
- Founded2002
- HeadquartersWashington, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What RiskAnalytics does
RiskAnalytics is a U.S.-based private cybersecurity company founded in 2002 and headquartered in Overland Park, Kansas, that provides real-time cyber threat intelligence through its ShadowNet platform. The platform tracks, sources, and correlates malicious traffic from distributed global sensors through a patented (filed/pending) machine-learning threat correlation engine, producing dynamic lists of domains and IPs actively involved in cybercrime that can be consumed in minutes rather than days. The company distributes its intelligence via multiple channels — SOC/SIEM feeds (with integrations for Palo Alto Networks and Splunk), Firefox/Chrome browser extensions, iOS/Android mobile apps, Threat Intelligence Gateway (TIG) hardware appliances in 1G and 10G configurations, and a customer API — alongside complementary products including ThreatSweep (network detection), IntelliShun (IP shunning), RAForce (customer portal), and RiskTool (cybersecurity workforce LMS).
RiskAnalytics generates revenue primarily through subscription-based threat intelligence licensing (with a free non-commercial tier available) and hardware sales of TIG/IntelliShun appliances. The company serves thousands of customers across business segments of all sizes, Managed Security Service Providers (MSSPs), insurance partners, and government entities — the latter primarily through ShadowNet Program registrations across 14+ Information Sharing and Analysis Centers (ISACs) including MS-ISAC, OT-ISAC, K12-SIX, H-ISAC, GRF, LS-ISAO, and the Elections Infrastructure ISAC. Distribution relies on a hybrid GTM motion combining enterprise field sales, channel/MSSP partnerships, and community-led growth anchored by its contributor membership in Google's VirusTotal community.
RiskAnalytics firmographics
Firmographics- Name
- RiskAnalytics
- Legal name
- RiskAnalytics
- Website
- https://riskanalytics.com
- Company type
- Private
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
RiskAnalytics industry classification
Industry- Product category
- Cybersecurity Threat Intelligence
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- akta.pro primary industry
- Deception Technology & Threat Hunting (HDADAGAI)
- akta.pro secondary industries
- Threat Intelligence Services (BPAEADAC), Fraud, Cybercrime Investigations & Brand/Dark Web Monitoring (BPAKAHAO)
Keywords
Where RiskAnalytics is headquartered
LocationHeadquarters
- HQ city
- Washington
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
RiskAnalytics business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Supply Chain
Revenue model
- ShadowNet Threat Intelligence Subscription: Subscription-based threat intelligence feed offered via multiple delivery methods including SOC/SIEM feeds, browser extensions, Threat Intelligence Gateways, and mobile apps. Commercial licensing for full threat intel feed with free non-commercial version available.
- Threat Intelligence Gateway Hardware: Sale of physical TIG (Threat Intelligence Gateway) appliances available in 1G or 10G configurations. Hardware boxes consumed and normalize threat intelligence feeds.
- RiskTool LMS Subscription: Learning Management System subscription for cybersecurity workforce training. Includes modules for training, policies, inspection checklists and assessments. Supports active directory integration and single sign-on.
- API Access: ShadowNet Customer API v2 provides unified dynamic IP and DNS lists in formats compatible with security appliances and SIEM platforms. Access provided to licensed subscribers through RAForce portal.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free trial available for ShadowNet threat intelligence |
Go-to-market motion3 records
Distribution channels6 records
Marketing channels5 records
RiskAnalytics product offering
Product offeringCore offering
RiskAnalytics operates ShadowNet, a real-time cyber threat intelligence platform that tracks, sources and correlates malicious traffic from distributed global sensors through a patented threat correlation engine. The resulting dynamic lists of malicious domains and IPs are delivered to customers via SOC/SIEM feeds, browser extensions, mobile apps, hardware Threat Intelligence Gateways (TIGs), and an API, with the goal of blocking threats outside the firewall before they can reach the customer's network.
Product overview
RiskAnalytics offers ShadowNet as its core threat intelligence platform, providing real-time cyber threat intelligence through multiple delivery methods including SOC/SIEM feeds, browser extensions, mobile apps, and physical Threat Intelligence Gateways (TIGs). The product portfolio includes complementary security tools: ThreatSweep for network detection and response, IntelliShun for IP shunning via hardware appliances, and RAForce as the customer management portal. Legacy community resources AutoShun and Malware Domains have been integrated into ShadowNet. RiskAnalytics also offers RiskTool, a separate learning management system for cybersecurity workforce training, covering policies, assessments, and compliance tasks.
Differentiator
Problem solved
Functional benefit
Brands
- ShadowNet: Real-time cyber threat intelligence feed that identifies and blocks malicious threats in minutes. ShadowNet tracks and correlates malicious traffic from distributed global sensors through a patented threat correlation engine, creating a dynamic list of domains and IPs actively involved in cyber-crime. Offered via SOC/SIEM feed, browser extension, threat intelligence gateway (TIG), and mobile app.
- IntelliShun
- ThreatSweep
- RAForce
- RiskTool
Products and services
- ShadowNet Threat Intelligence Platform
Quantifiable outcome
- Billions of attacks prevented in last year alone
- +2 more outcomes
Companies that use RiskAnalytics
Customer profileNamed customers3 records
Segments3 records
Ideal customer profiles4 records
RiskAnalytics technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
AI capability3 records
Feature10 records
RiskAnalytics partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core.
- Google VirusTotalcoreInvited contributor to Google's VirusTotal, part of an exclusive community that scores and rates malware samples, IPs and domains. Serves Fortune 500 companies, governments and leading security organizations. RiskAnalytics is among small community of cybersecurity experts helping analyze and identify malicious threats, sharing knowledge and expertise with Google.
- MS-ISAC (Multi-State ISAC)coreShadowNet Program registration available for MS-ISAC members. Partnership for providing threat intelligence to state, local, tribal, and territorial government entities.
- OT-ISAC (Operational Technology ISAC)coreShadowNet Program registration available for OT-ISAC members. Partnership for operational technology threat intelligence sharing.
- K12-SIX (K-12 Cybersecurity ISAC)coreShadowNet Program registration available for K12-SIX members. Partnership providing cybersecurity protection for K-12 educational institutions.
- GRF (Global Resilience Federation)coreShadowNet Program registration available for GRF members. Partnership for resilience and security intelligence sharing.
- H-ISAC (Health ISAC)coreShadowNet Program registration available for H-ISAC members. Partnership for healthcare sector threat intelligence.
- LS-ISAO (Logical Security ISAO)coreShadowNet Program registration available for LS-ISAO members. Partnership for logical security information sharing.
- National Council of ISACscoreShadowNet Program registration available through National Council of ISACs umbrella organization.
Scale indicators4 records
Recent moves1 record
Expansion highlights6 records
RiskAnalytics competitors and assessment
Company assessmentEmerging players
- Kaspersky Threat Intelligence: Kaspersky's Threat Intelligence Portal offers paid feeds of IP/domain/file reputation and threat data reports — partial overlap with ShadowNet's IP/DNS feeds and reporting, though delivered through a broader consumer- and enterprise-security portfolio.
- Cofense (formerly PhishLabs): Cofense / PhishLabs focuses on phishing-specific threat intelligence and email-security response, narrower than RiskAnalytics' IP/DNS feed but overlapping on threat feeds that protect against phishing and malware domains.
Broad incumbents
- Mandiant (Google Cloud): Mandiant (acquired by Google) combines threat intelligence with incident response, managed defense and consulting — overlapping with RiskAnalytics on the threat-intel feed and asset-monitoring layers but as part of a much broader services-led portfolio.
- CrowdStrike: CrowdStrike Falcon Intelligence is a threat-intel module bundled into its endpoint/XDR platform. As enterprise security stacks consolidate onto endpoint platforms, CrowdStrike represents both an integration partner and a bundled competitor to a standalone ShadowNet subscription.
- Palo Alto Networks (Unit 42): Palo Alto Networks ships AutoFocus / Unit 42 threat intelligence as part of its wider firewall and Cortex platform. RiskAnalytics already integrates with Palo Alto firewalls via its API, making the larger vendor both a partner-channel and a potential competitive substitute.
Direct peers
- Recorded Future: Recorded Future is the largest pure-play commercial cyber threat-intelligence platform, offering real-time intelligence feeds, branded threat reports and APIs consumed by SIEMs and security teams. Like RiskAnalytics, its core product is a continuously refreshed IP/domain/malware intelligence feed with machine-learning correlation — making it the closest direct competitor to ShadowNet.
- Flashpoint: Flashpoint delivers cyber-threat and physical-risk intelligence, including compromised credentials and dark-web monitoring; comparable to RiskAnalytics' cybercrime-tracking feed and the brand/dark-web-adjacent use cases its MSSP/insurance customers care about.
- ThreatConnect: ThreatConnect delivers a threat-intelligence platform (CAL™ platform) that fuses intelligence, automation and analytics to support SOC workflows; it is a direct functional peer to ShadowNet's feed-and-API architecture.
- Anomali: Anomali provides a threat-intelligence platform (Anomali ThreatStream) that aggregates feeds, supports STIX/TAXII and integrates with SIEMs and SOAR — directly comparable to RiskAnalytics' ShadowNet feed + API + Splunk/Palo Alto integrations.
- Digital Shadows (now part of ReliaQuest): Digital Shadows was a pure-play threat-intelligence vendor offering digital risk monitoring, brand/exposure intelligence and IOC feeds — closely comparable to RiskAnalytics' ShadowNet feed and IntelliShun blocking capabilities, now integrated into ReliaQuest's broader GreyMatter platform.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
RiskAnalytics social profiles
Digital presenceRiskAnalytics financial estimates
Financial estimateRevenue estimate
Valuation estimate
RiskAnalytics leadership team
Management profileNumber of profiles
Profiles5 records
RiskAnalytics subsidiaries and ownership
Company hierarchySubsidiaries2 records
RiskAnalytics funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
RiskAnalytics M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about RiskAnalytics
What does RiskAnalytics do?
RiskAnalytics operates ShadowNet, a real-time cyber threat intelligence platform that tracks, sources and correlates malicious traffic from distributed global sensors through a patented threat correlation engine. The resulting dynamic lists of malicious domains and IPs are delivered to customers via SOC/SIEM feeds, browser extensions, mobile apps, hardware Threat Intelligence Gateways (TIGs), and an API, with the goal of blocking threats outside the firewall before they can reach the customer's network.
Is RiskAnalytics a public or private company?
RiskAnalytics is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was RiskAnalytics founded?
RiskAnalytics was founded in 2002. It employs 11 to 50 people.
Where is RiskAnalytics based?
RiskAnalytics is headquartered in Washington, United States, in the North America region.
How does RiskAnalytics make money?
Four revenue lines are on record. ShadowNet Threat Intelligence Subscription is the primary driver. The others are threat Intelligence Gateway Hardware, riskTool LMS Subscription and API Access.
Who are RiskAnalytics's main competitors?
Emerging players on record are Kaspersky Threat Intelligence and Cofense (formerly PhishLabs). Broad incumbents are Mandiant (Google Cloud), CrowdStrike and Palo Alto Networks (Unit 42). Direct peers are Recorded Future, Flashpoint, ThreatConnect, Anomali and Digital Shadows (now part of ReliaQuest).
Does RiskAnalytics have an API?
Yes. ShadowNet Customer API v2 provides unified dynamic IP and DNS lists in formats that load directly into security appliances and SIEM platforms. Two endpoints are available: (1) unified text feed with one IP/CIDR per line for all subscribed IP lists, and (2) unified text feed with one Domain/FQDN per line for all subscribed DNS lists. Default IP Lists protect against Reconnaissance scanners, Brute Force, Application Exploits, Malware, Phishing sites and other observed threats. DNS Feeds include RiskAnalytics' own MalwareDomains.com list, ActiveMalware and FastFlux DNS feeds, and optional lists for Ransomware, Remote Access and Banking Trojans. Documentation available to licensed subscribers from inside RAForce portal. Developer documentation is at support.riskanalytics.com/support/solutions/articles/12000036137-shadownet-customer-api-v2.
What industry is RiskAnalytics in?
RiskAnalytics's product category is Cybersecurity Threat Intelligence. Its primary akta.pro industry code is HDADAGAI, Deception Technology & Threat Hunting, with a secondary code of BPAEADAC, Threat Intelligence Services. Its NAICS code is 561621.